Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Dec 2005 23:06:41 +0530
From:      Abhi <soman.abhijit@gmail.com>
To:        freebsd-questions@freebsd.org
Subject:   Re: 6.0 Release kernel panic - page fault
Message-ID:  <a56744b40512230936y6adb573q28f3220f4b5d3ebf@mail.gmail.com>
In-Reply-To: <441x033m21.fsf@be-well.ilk.org>
References:  <a56744b40512220857w409559d5r83fd7374de86c17b@mail.gmail.com> <441x033m21.fsf@be-well.ilk.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Hello,
   Thanks for your reply. Actually i experienced page faults mostly
when browsing web mostly from linux opera. So i installed firefox from
ports. It didnt cause any panic until yeserday, when it caused the
crash. And after that system panic occured while booting. Well i don't
know if a particular application is causing system panic but most
panics occured when i was using net.
Can you tell me if there are any other options for kernel
configuration file which can make the debugging mor verbose? I only
used -g option in my kernel config.
I'm attaching another crash dump which occurred last night when i was
browsing net.

Greetings,
Abhijit
------------
kernel dump

Unread portion of the kernel message buffer:
panic: clist reservation botch
Uptime: 1h4m51s
Dumping 510 MB (2 chunks)
  chunk 0: 1MB (159 pages) ... ok
  chunk 1: 510MB (130528 pages) 494 478 462 446 430 414 398 382 366 350 334=
 318
302 286 270 254 238 222 206 190 174 158 142 126 110 94 78 62 46 30 14

#0  doadump () at pcpu.h:165
165             __asm __volatile("movl %%fs:0,%0" : "=3Dr" (td));

(kgdb) where
#0  doadump () at pcpu.h:165
#1  0xc04c524a in boot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:3=
99
#2  0xc04c54e0 in panic (fmt=3D0xc06266e5 "clist reservation botch")
    at /usr/src/sys/kern/kern_shutdown.c:555
#3  0xc04f90be in b_to_q (
    src=3D0xc18318ae "ept: */*\r\nAccept-Language: en-us,en;q=3D0.5\r\nAcce=
pt-Encodi
ng: gzip,deflate\r\nAccept-Charset: ISO-8859-1,utf-8;q=3D0.7,*;q=3D0.7\r\nK=
eep-Alive
: 300\r\nConnection: keep-alive\r\nReferer: http://www.hi5.com/friend/di"..=
., am
ount=3D704, clistp=3D0xc1669838) at /usr/src/sys/kern/tty_subr.c:104
#4  0xc0539e44 in pppasyncstart (sc=3D0xc1a3c400)
    at /usr/src/sys/net/ppp_tty.c:582
#5  0xc053539e in pppoutput (ifp=3D0xc1636400, m0=3D0xc171cb00, dst=3D0xc1b=
64310,
    rtp=3D0xc17dbb58) at /usr/src/sys/net/if_ppp.c:961
#6  0xc054be9c in ip_output (m=3D0xc171cb00, opt=3D0xc1636400, ro=3D0xd5440=
bb0,
    flags=3D0, imo=3D0x0, inp=3D0xc1814a8c) at /usr/src/sys/netinet/ip_outp=
ut.c:776
#7  0xc0554bfa in tcp_output (tp=3D0xc1bddac8)
    at /usr/src/sys/netinet/tcp_output.c:1080
#8  0xc055a661 in tcp_timer_rexmt (xtp=3D0xc1bddac8)
    at /usr/src/sys/netinet/tcp_timer.c:579
#9  0xc04d12cf in softclock (dummy=3D0x0)
    at /usr/src/sys/kern/kern_timeout.c:290
#10 0xc04b0e41 in ithread_loop (arg=3D0xc1581480)
    at /usr/src/sys/kern/kern_intr.c:547
#11 0xc04b00c8 in fork_exit (callout=3D0xc04b0ce8 <ithread_loop>,
    at /usr/src/sys/kern/kern_shutdown.c:555
#3  0xc04f90be in b_to_q (
    src=3D0xc18318ae "ept: */*\r\nAccept-Language: en-us,en;q=3D0.5\r\nAcce=
pt-Encodi
ng: gzip,deflate\r\nAccept-Charset: ISO-8859-1,utf-8;q=3D0.7,*;q=3D0.7\r\nK=
eep-Alive
: 300\r\nConnection: keep-alive\r\nReferer: http://www.hi5.com/friend/di"..=
., am
ount=3D704, clistp=3D0xc1669838) at /usr/src/sys/kern/tty_subr.c:104
#4  0xc0539e44 in pppasyncstart (sc=3D0xc1a3c400)
    at /usr/src/sys/net/ppp_tty.c:582
#5  0xc053539e in pppoutput (ifp=3D0xc1636400, m0=3D0xc171cb00, dst=3D0xc1b=
64310,
    rtp=3D0xc17dbb58) at /usr/src/sys/net/if_ppp.c:961
#6  0xc054be9c in ip_output (m=3D0xc171cb00, opt=3D0xc1636400, ro=3D0xd5440=
bb0,
    flags=3D0, imo=3D0x0, inp=3D0xc1814a8c) at /usr/src/sys/netinet/ip_outp=
ut.c:776
#7  0xc0554bfa in tcp_output (tp=3D0xc1bddac8)
    at /usr/src/sys/netinet/tcp_output.c:1080
#8  0xc055a661 in tcp_timer_rexmt (xtp=3D0xc1bddac8)
    at /usr/src/sys/netinet/tcp_timer.c:579
#9  0xc04d12cf in softclock (dummy=3D0x0)
    at /usr/src/sys/kern/kern_timeout.c:290
#10 0xc04b0e41 in ithread_loop (arg=3D0xc1581480)
    at /usr/src/sys/kern/kern_intr.c:547
#11 0xc04b00c8 in fork_exit (callout=3D0xc04b0ce8 <ithread_loop>,
    arg=3D0xc1581480, frame=3D0xd5440d38) at /usr/src/sys/kern/kern_fork.c:=
789
#12 0xc05ebe2c in fork_trampoline () at /usr/src/sys/i386/i386/exception.s:=
208

(kgdb) bt full
#0  doadump () at pcpu.h:165
No locals.
#1  0xc04c524a in boot (howto=3D260) at /usr/src/sys/kern/kern_shutdown.c:3=
99
        first_buf_printf =3D 1
#2  0xc04c54e0 in panic (fmt=3D0xc06266e5 "clist reservation botch")
    at /usr/src/sys/kern/kern_shutdown.c:555
        td =3D (struct thread *) 0xc15cb480
        bootopt =3D 260
        newpanic =3D 0
        ap =3D 0xc15cb480 "0=A8\\=C1 uX=C1"
        buf =3D "clist reservation botch", '\0' <repeats 232 times>
#3  0xc04f90be in b_to_q (
    src=3D0xc18318ae "ept: */*\r\nAccept-Language: en-us,en;q=3D0.5\r\nAcce=
pt-Encodi
ng: gzip,deflate\r\nAccept-Charset: ISO-8859-1,utf-8;q=3D0.7,*;q=3D0.7\r\nK=
eep-Alive
: 300\r\nConnection: keep-alive\r\nReferer: http://www.hi5.com/friend/di"..=
., am
ount=3D704, clistp=3D0xc1669838) at /usr/src/sys/kern/tty_subr.c:104
        prev =3D (struct cblock *) 0x0
        cblockp =3D (struct cblock *) 0xc1af9380
        firstbyte =3D 0xc0c293c0 " \223=C2=C0`\224=C2=C0=C4=C9d=C0=C0)b=C0z=
\ac=C0"
        lastbyte =3D 0x3 <Address 0x3 out of bounds>
        startmask =3D 0 '\0'
        endmask =3D 0 '\0'
        startbit =3D 0
        endbit =3D -1067774825
      num_between =3D 0
        numc =3D 108
#4  0xc0539e44 in pppasyncstart (sc=3D0xc1a3c400)
    at /usr/src/sys/net/ppp_tty.c:582
        tp =3D (struct tty *) 0xc1669800
        m =3D (struct mbuf *) 0xc171bd00
        len =3D 878
        start =3D (
    u_char *) 0xc1831800 "GET /w/get.media?sid=3D16683&m=3D1&tp=3D5&d=3Dj&t=
=3Ds HTTP/1.1\r
\nHost: media.fastclick.net\r\nUser-Agent: Mozilla/5.0 (X11; U; FreeBSD i38=
6; en
-US; rv:1.8) Gecko/20051219 Firefox/1.5\r\nAccept: */*\r\nAccept-Language:"=
...
        stop =3D (u_char *) 0xc1831b6e "\001"
        cp =3D (u_char *) 0x0
        n =3D 878
        ndone =3D 0
        done =3D 1
        idle =3D 0
#5  0xc053539e in pppoutput (ifp=3D0xc1636400, m0=3D0xc171cb00, dst=3D0xc1b=
64310,
    rtp=3D0xc17dbb58) at /usr/src/sys/net/if_ppp.c:961
        sc =3D (struct ppp_softc *) 0xc1a3c400
        protocol =3D 33
        address =3D 255
        control =3D 3
       cp =3D (u_char *) 0x0
        error =3D -1050450696
        ip =3D (struct ip *) 0x0
        ifq =3D (struct ifqueue *) 0xc16364f8
        mode =3D NPMODE_PASS
        len =3D 922
#6  0xc054be9c in ip_output (m=3D0xc171cb00, opt=3D0xc1636400, ro=3D0xd5440=
bb0,
    flags=3D0, imo=3D0x0, inp=3D0xc1814a8c) at /usr/src/sys/netinet/ip_outp=
ut.c:776
        ip =3D (struct ip *) 0xc171cb40
        ifp =3D (struct ifnet *) 0xc1636400
        m0 =3D (struct mbuf *) 0xc171cb40
        hlen =3D 20
        len =3D -716960796
        error =3D 0
        dst =3D (struct sockaddr_in *) 0xc1b64310
        ia =3D (struct in_ifaddr *) 0xc1a8fd00
        isbroadcast =3D 0
        sw_csum =3D 1
        iproute =3D {ro_rt =3D 0xc17dbb58, ro_dst =3D {sa_len =3D 16 '\020'=
,
    sa_family =3D 2 '\002',
    sa_data =3D "\000\000=CD=B4V\016\000\000\000\000\000\000\000"}}
        odst =3D {s_addr =3D 1}
#7  0xc0554bfa in tcp_output (tp=3D0xc1bddac8)
    at /usr/src/sys/netinet/tcp_output.c:1080
        so =3D (struct socket *) 0xc1b5fb20
        len =3D 878
        recwin =3D 65535
        sendwin =3D -1049506988
        off =3D 0
        flags =3D 24
        error =3D 0
        m =3D (struct mbuf *) 0xc171cb00
        ip =3D (struct ip *) 0xc171cb40
        th =3D (struct tcphdr *) 0xc171cb54
        opt =3D "p\fD=D5=BEeM=C0\000=F3f=C0T\201=B5=C1\000\000\000\000\200\=
fD=D5=EDfM=C0\203\000\000\0
00=A3dM=C0\200=B4\\=C1"
        ipoptlen =3D 0
        optlen =3D 0
        hdrlen =3D 40
        idle =3D 0
        sendalot =3D 0
        i =3D -1068669610
        sack_rxmit =3D 0
        sack_bytes_rxmt =3D 0
        p =3D (struct sackhole *) 0x0
        ip6 =3D (struct ip6_hdr *) 0x0
        isipv6 =3D 0
#8  0xc055a661 in tcp_timer_rexmt (xtp=3D0xc1bddac8)
        so =3D (struct socket *) 0xc1b5fb20
        len =3D 878
        recwin =3D 65535
        sendwin =3D -1049506988
        off =3D 0
        flags =3D 24
        error =3D 0
        m =3D (struct mbuf *) 0xc171cb00
        ip =3D (struct ip *) 0xc171cb40
        th =3D (struct tcphdr *) 0xc171cb54
        opt =3D "p\fD=D5=BEeM=C0\000=F3f=C0T\201=B5=C1\000\000\000\000\200\=
fD=D5=EDfM=C0\203\000\000\0
00=A3dM=C0\200=B4\\=C1"
        ipoptlen =3D 0
        optlen =3D 0
        hdrlen =3D 40
        idle =3D 0
        sendalot =3D 0
        i =3D -1068669610
        sack_rxmit =3D 0
        sack_bytes_rxmt =3D 0
        p =3D (struct sackhole *) 0x0
        ip6 =3D (struct ip6_hdr *) 0x0
        isipv6 =3D 0
#8  0xc055a661 in tcp_timer_rexmt (xtp=3D0xc1bddac8)
 at /usr/src/sys/netinet/tcp_timer.c:579
        tp =3D (struct tcpcb *) 0xc1bddac8
        rexmt =3D 0
        headlocked =3D 0
        inp =3D (struct inpcb *) 0xc1814a8c
#9  0xc04d12cf in softclock (dummy=3D0x0)
    at /usr/src/sys/kern/kern_timeout.c:290
        c_func =3D (void (*)(void *)) 0xc055a2f4 <tcp_timer_rexmt>
        c_arg =3D (void *) 0xc1bddac8
        c_mtx =3D (struct mtx *) 0x0
        c_flags =3D 22
        c =3D (struct callout *) 0x0
        bucket =3D (struct callout_tailq *) 0xcbb66670
        curticks =3D 3891132
        steps =3D 0
        depth =3D 1
        mpcalls =3D 1
        mtxcalls =3D 0
        gcalls =3D 0
        wakeup_cookie =3D 0
#10 0xc04b0e41 in ithread_loop (arg=3D0xc1581480)
    at /usr/src/sys/kern/kern_intr.c:547
        ithd =3D (struct ithd *) 0xc1581480
        ih =3D (struct intrhand *) 0xc157b2c0
        c =3D (struct callout *) 0x0
        bucket =3D (struct callout_tailq *) 0xcbb66670
        curticks =3D 3891132
        steps =3D 0
        depth =3D 1
        mpcalls =3D 1
        mtxcalls =3D 0
        gcalls =3D 0
        wakeup_cookie =3D 0
#10 0xc04b0e41 in ithread_loop (arg=3D0xc1581480)
    at /usr/src/sys/kern/kern_intr.c:547
        ithd =3D (struct ithd *) 0xc1581480
        ih =3D (struct intrhand *) 0xc157b2c0
---Type <return> to continue, or q <return> to quit---
        td =3D (struct thread *) 0xc15cb480
        p =3D (struct proc *) 0xc15ca830
        count =3D 0
        warned =3D 0
#11 0xc04b00c8 in fork_exit (callout=3D0xc04b0ce8 <ithread_loop>,
    arg=3D0xc1581480, frame=3D0xd5440d38) at /usr/src/sys/kern/kern_fork.c:=
789
        p =3D (struct proc *) 0xc15ca830
        td =3D (struct thread *) 0x0
#12 0xc05ebe2c in fork_trampoline () at /usr/src/sys/i386/i386/exception.s:=
208
No locals.



On 23 Dec 2005 09:49:58 -0500, Lowell Gilbert
<freebsd-questions-local@be-well.ilk.org> wrote:
> Abhi <soman.abhijit@gmail.com> writes:
>
> >    I'm experiencing kernel panics with 6.0 Release. I did a fresh
> > install of 6.0 Release after playing with some linux distros and
> > Freebsd 5.4 Release. The only problem i had was due to faulty RAM. I
> > replaced the RAM and had no problems. But  for somedays my system has
> > started to panic randomly. All the crash dumps i got show something
> > wrong in the file pcpu.h at line 165.
>
> That just means it's dumping core.  You need to look a little
> deeper for why it's doing so.
>
> >  I'm ttaching my custom kernel configuration file and one crash dump i
> > got with kgdb. I hope someone can tell me why this's happening, and if
> > this's freebsd problem or  hardware problem.
>
> In this case, it's smashing its own stack while doing a bcopy()
> (or some related function).  If that's not consistent, this
> probably *is* a hardware problem.  If it's dependable, then maybe
> not.  Try to track down commonalities in what the system is doing
> when it panics.  If possible.
>


--
If Karl, instead of writing a lot about Capital, had made a lot of
Capital, it would have been much better.
                -- Karl Marx's Mother



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?a56744b40512230936y6adb573q28f3220f4b5d3ebf>